CWE-287
CVEs classified under CWE-287, newest first.
462 CVEsRSS
CVE-2026-60678High· 8.8Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…
CVE-2026-61311High· 8.8Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…
CVE-2026-61188High· 7.5Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privile…
CVE-2026-61183Critical· 9.8Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated …
CVE-2026-61180High· 8.8Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…
CVE-2026-61179High· 8.8Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…
CVE-2026-61178Critical· 9.8Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticat…
CVE-2026-61110High· 8.8Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch)
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …
CVE-2026-60615High· 8.2Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with …
CVE-2026-60599High· 8.1Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacke…
CVE-2026-60598High· 7.5Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attac…
CVE-2026-60568Critical· 9.9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged att…
CVE-2026-60558High· 8.1Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated…
CVE-2026-56654HighGitea: Privilege Escalation via Access Token Scope Escalation in API
Gitea: Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-58423High· 7.7Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-61740CriticalLightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CVE-2026-16210High· 7.3A vulnerability was found in newpanjing simpleui 2026.01.13
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. R…
CVE-2026-16209High· 7.3A vulnerability has been found in Gerapy up to 0.9.13
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The a…
CVE-2026-16198Medium· 5.6A vulnerability was detected in Sipeed PicoClaw up to 0.2.9
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument all…
CVE-2024-58363Medium· 6.3SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method
SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database i…
CVE-2026-47865Critical· 9.8VMware Avi Load Balancer contains an authentication bypass vulnerability
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2…
CVE-2026-16083Medium· 5.3A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by …
CVE-2026-16076Medium· 6.3A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username …
CVE-2026-22752Critical· 9.6Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1…
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1…
CVE-2026-55445NoneQinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript
Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not /open/user/init, while rewrite('/open…
CVE-2026-52893NoneWekan is open source kanban built with Meteor
Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, withou…
CVE-2026-45363Critical· 9.1ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', paylo…
CVE-2026-50338High· 8.2PoCAzure Spring Apps Elevation of Privilege Vulnerability
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-57107High· 7.8Windows Admin Center Elevation of Privilege Vulnerability
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
CVE-2026-56185Medium· 6.5Windows Admin Center Information Disclosure Vulnerability
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.